<Note>

This engine can use external X.509 certificates as part of TLS or signature validation.
Verifying signatures against X.509 certificates that use SHA-1 is deprecated and is no longer
usable without a workaround starting in Vault 1.12. Refer to the
[deprecation notices](/vault/docs/updates/deprecation)
for more information.

</Note>